{"id":8736,"date":"2025-11-26T10:00:47","date_gmt":"2025-11-26T10:00:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/26\/yamagoya-real-time-threat-monitoring-tool-using-sigma-and-yara-rules\/"},"modified":"2025-11-26T10:00:47","modified_gmt":"2025-11-26T10:00:47","slug":"yamagoya-real-time-threat-monitoring-tool-using-sigma-and-yara-rules","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/26\/yamagoya-real-time-threat-monitoring-tool-using-sigma-and-yara-rules\/","title":{"rendered":"YAMAGoya \u2013 Real-Time Threat Monitoring Tool Using Sigma and YARA Rules"},"content":{"rendered":"<p>    YAMAGoya \u2013 Real-Time Threat Monitoring Tool Using Sigma and YARA Rules<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Modern cybersecurity faces an escalating challenge: fileless malware and obfuscation techniques increasingly bypass traditional file-based detection methods.<\/p>\n<p>To address this growing threat, JPCERT\/CC has released YAMAGoya. This open-source threat hunting tool leverages industry-standard detection rules to identify suspicious activity in real time.<\/p>\n<p>YAMAGoya represents a significant advancement in endpoint threat detection by combining <a href=\"https:\/\/cybersecuritynews.com\/event-tracing-over-eventlog-for-windows\/\" target=\"_blank\" rel=\"noreferrer noopener\">Event Tracing for Windows<\/a> (ETW) event monitoring with memory scanning capabilities.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-open-source-endpoint-detection-solution\"><strong>Open-Source Endpoint Detection Solution <\/strong><\/h2>\n<p>Unlike conventional security tools that rely on proprietary detection engines, YAMAGoya directly supports Sigma and YARA rules.<\/p>\n<p>Enabling security analysts to deploy community-driven detection logic across their infrastructure.<\/p>\n<p>The tool operates entirely in userland, requiring no kernel driver installation, which simplifies deployment across organizational environments.<\/p>\n<p>Its <a href=\"https:\/\/cybersecuritynews.com\/how-to-build-a-zero-trust-strategy-around-real-time-credential-monitoring\/\" target=\"_blank\" rel=\"noreferrer noopener\">real-time monitoring<\/a> capabilities track files, processes, registry modifications, DNS queries, network connections, PowerShell execution, and WMI commands simultaneously.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj_IB1NS9TGryq-8dJwJq-SLWCf9qJ1Cdmfa9siHHrKu4g2q8J4-mqZudYCc55o4LK6OnV6gC7SZCRZb1VcHWClVLkoONyXg0ro58lV76UoL9CWicjp59Fbh3g5shDKJO-5-rtDFFUZfgI51P4j-CKZ5eHXocpwrAleEYOAalH69kQwxcfd5sFv0SBcSl8\/s1600\/Screenshot%25202025-11-18%2520182926%2520%25281%2529.webp?ssl=1\" alt=\"YAMAGoya startup screen\"><figcaption class=\"wp-element-caption\">YAMAGoya startup screen<\/figcaption><\/figure>\n<p>This comprehensive approach enables the detection of both traditional and fileless malware threats.<\/p>\n<p>According to JPCERT\/CC, YAMAGoya supports multiple rule formats, including Sigma rules, YARA rules for memory scanning, and custom YAML rules for correlation-based detection.<\/p>\n<p>JPCERT\/CC security teams can create sophisticated detection logic that correlates multiple events.<\/p>\n<p>Such as file creation followed by process execution, <a href=\"https:\/\/cybersecuritynews.com\/mustang-panda-using-new-dll-side-loading\/\" target=\"_blank\" rel=\"noreferrer noopener\">DLL loading<\/a>, and network communication, to identify malicious activity patterns.<\/p>\n<p>The tool is available for immediate evaluation through pre-built binaries on GitHub, with source code available for organizations requiring custom builds.<\/p>\n<p>YAMAGoya operates via both graphical and <a href=\"https:\/\/cybersecuritynews.com\/command-line-obfuscation-bypasses-avs-edrs\/\" target=\"_blank\" rel=\"noreferrer noopener\">command-line<\/a> interfaces, accommodating different operational preferences.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEinExB2UDBnLN0SOVEkWH6H6r8k_0qY-fXehNXuBcB2adnLMHQsxqa8zLMPH_OahzjXkDv_AIxCU3hK25TArhlGzDYqKkG9WCTg7OmO8FPbBVgHWV20GEO9egOhTvC6zEjhBADSn0syak00uPszjcK9MI3WE4kNfBJ6_h72foZ_Rp6g6D3qCZBonCU3hEM\/s1600\/Screenshot%25202025-11-18%2520185207%2520%25281%2529.webp?ssl=1\" alt=\"YAMAGoya's Alert tab\"><figcaption class=\"wp-element-caption\">YAMAGoya\u2019s Alert tab<\/figcaption><\/figure>\n<p>Users can run Sigma rule monitoring or memory scanning with simple commands, provided they have administrative privileges.<\/p>\n<p>JPCERT\/CC detection<a href=\"https:\/\/blogs.jpcert.or.jp\/en\/2025\/11\/YAMAGoya.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> alerts<\/a> appear in the tool\u2019s interface. They are logged to <a href=\"https:\/\/cybersecuritynews.com\/windows-event-log-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Event Log <\/a>with specific event IDs for integration with security information and event management (SIEM) systems.<\/p>\n<p>This enables centralized monitoring and alerting across enterprise environments. By supporting industry-standard detection rules, YAMAGoya democratizes advanced <a href=\"https:\/\/cybersecuritynews.com\/advanced-threat-detection-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">threat detection <\/a>capabilities.<\/p>\n<p>JPCERT\/CC researchers and incident responders can now leverage community-developed Sigma and YARA rules without vendor lock-in, strengthening the collective cybersecurity defense posture against emerging threats.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/yamagoya-real-time-threat-monitoring-tool\/\">YAMAGoya \u2013 Real-Time Threat Monitoring Tool Using Sigma and YARA Rules<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/yamagoya-real-time-threat-monitoring-tool\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>YAMAGoya \u2013 Real-Time Threat Monitoring Tool Using Sigma and YARA Rules Modern cybersecurity faces an escalating challenge: fileless malware and obfuscation techniques increasingly bypass traditional file-based detection methods. To address this growing threat, JPCERT\/CC has released YAMAGoya. This open-source threat hunting tool leverages industry-standard detection rules to identify suspicious activity in real time. YAMAGoya represents [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,1709],"tags":[130],"class_list":["post-8736","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-cyberpedia","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8736"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8736"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8736\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8736"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8736"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}